{
  "model": "grayson-1",
  "context": {
    "alert": {
      "alert_id": "TI-20261007-0412",
      "received": "2026-10-07T13:52:00Z",
      "vendor": "Threat intelligence vendor, dark web monitoring feed",
      "alert_type": "Online banking access offered for sale (a 'bank log' listing)",
      "listing": {
        "posted": "2026-10-06T19:22:00Z",
        "venue": "Invite-only marketplace on Tor",
        "seller": {
          "first_seen_by_vendor": "2025-02",
          "listings_seen_by_vendor": 214,
          "marketplace_rating": "4.8 of 5"
        },
        "title": "NORTHWIND BANK | chk + sav | bal 24k+ | email access | cookies",
        "price_usd": 260,
        "seller_claims": [
          "Online banking login",
          "Access to the holder's email account",
          "Browser cookies",
          "Holder's full name, date of birth and address"
        ],
        "screenshot_extract": {
          "method": "Vendor text extraction from the seller's screenshot",
          "name_shown": "Dana W.",
          "accounts_shown": [
            {
              "type": "checking",
              "last4": "4417",
              "balance_usd": 18412.67
            },
            {
              "type": "savings",
              "last4": "9032",
              "balance_usd": 6050
            }
          ],
          "clock_shown": "Sep 29, 9:16 PM",
          "browser_shown": "Chrome on Windows"
        }
      },
      "linked_credential_record": {
        "source": "Infostealer log (malware on the holder's computer)",
        "captured": "2026-09-28T23:40:00Z",
        "machine": "Windows 11, Chrome",
        "sites_in_log": 38,
        "entries_for_our_bank": "Online banking username and password, and 4 browser cookies for online.northwind-bank.example",
        "other_entries_of_note": "Password for the email account on file",
        "device_match": "The log's machine name and browser fingerprint match the customer's trusted Windows laptop"
      },
      "vendor_match": {
        "matched_on": [
          "online banking username",
          "account last four 4417 and 9032",
          "first name and last initial"
        ],
        "vendor_confidence": "high"
      }
    },
    "customer": {
      "customer_id": "cus_20817",
      "name": "Dana Whitfield",
      "customer_since": "2014-05-19",
      "accounts": [
        {
          "type": "checking",
          "last4": "4417",
          "status": "open"
        },
        {
          "type": "savings",
          "last4": "9032",
          "status": "open"
        }
      ],
      "online_banking_username_matches_alert": true,
      "sign_in_security": "SMS one-time code to the phone on file for new devices, new payees and contact changes; trusted devices skip the code at sign-in. 'Forgot password' emails a reset link to the email on file, and a trusted device skips the one-time code after a reset",
      "trusted_devices": [
        {
          "device": "iPhone 15, iOS 18",
          "trusted_since": "2023-11-02"
        }
      ],
      "removed_trusted_devices": [
        {
          "device": "Windows 11 laptop, Chrome",
          "trusted_since": "2022-03-14",
          "removed": "2026-09-30T01:25:00Z"
        }
      ],
      "phone_on_file_last_changed": "2019-08-01",
      "email_on_file": "d.whitfield@example.net",
      "email_on_file_last_changed": "2018-02-11",
      "debit_card": {
        "last4": "2291",
        "status": "active",
        "issued": "2025-06-03",
        "declines_last_30_days": 0
      }
    },
    "balance_check": {
      "ledger_at_screenshot_time": {
        "as_of": "2026-09-30T01:16:00Z",
        "checking_4417_usd": 18412.67,
        "savings_9032_usd": 6050
      },
      "ledger_now": {
        "as_of": "2026-10-07T14:00:00Z",
        "checking_4417_usd": 16980.12,
        "savings_9032_usd": 6050
      }
    },
    "credential_check": {
      "method": "Vendor-supplied password hashed with this login's stored salt and algorithm and compared with the stored hashes; the plaintext was discarded and never logged",
      "matches_current_password": false,
      "matches_a_previous_password": true,
      "current_password_set": "2026-10-01T12:58:00Z",
      "current_password_set_from": "iPhone 15 (trusted device), home IP 203.0.113.41, after a one-time code",
      "trusted_device_token": "The laptop's trusted-device token stopped working when the laptop was removed from trusted devices on 2026-09-30"
    },
    "sign_in_events": [
      {
        "ts": "2026-09-26T23:02:00Z",
        "device": "Windows 11 laptop, Chrome (trusted)",
        "ip": "203.0.113.41",
        "network": "Residential broadband",
        "code_required": false,
        "result": "success"
      },
      {
        "ts": "2026-09-29T22:40:00Z",
        "device": "iPhone 15 (trusted)",
        "ip": "203.0.113.41",
        "network": "Residential broadband",
        "code_required": false,
        "result": "success"
      },
      {
        "ts": "2026-09-30T01:14:00Z",
        "device": "Windows 11, Chrome, presented the laptop's trusted-device cookie",
        "ip": "198.51.100.73",
        "network": "Hosting provider",
        "ip_location": "Amsterdam, NL",
        "code_required": false,
        "result": "success; viewed account summary; signed out 01:19"
      },
      {
        "ts": "2026-09-30T01:20:00Z",
        "event": "SMS sent to phone on file: 'New sign-in from Amsterdam, NL. Was this you? Reply YES or NO.'"
      },
      {
        "ts": "2026-09-30T01:25:00Z",
        "event": "Customer replied NO. All sessions ended, the Windows laptop removed from trusted devices, and a password change required at next sign-in."
      },
      {
        "ts": "2026-10-01T12:55:00Z",
        "device": "iPhone 15 (trusted)",
        "ip": "203.0.113.41",
        "network": "Residential broadband",
        "code_required": true,
        "result": "success; one-time code entered; password changed at 12:58"
      },
      {
        "period": "2026-10-01T13:00:00Z to 2026-10-07T14:00:00Z",
        "summary": "9 sign-ins, all from the trusted iPhone on 203.0.113.41; the laptop hasn't signed in since it was removed; no new devices; no failed attempts"
      }
    ],
    "profile_changes_last_90_days": [
      {
        "ts": "2026-10-01T12:58:00Z",
        "change": "Password changed (required after the 2026-09-30 sign-in alert)"
      }
    ],
    "payees_added_last_90_days": [],
    "outbound_payments_since_2026-09-28": [
      {
        "ts": "2026-10-01T16:00:00Z",
        "type": "Bill payment",
        "payee": "Electric utility (payee since 2016)",
        "amount_usd": 142.18
      },
      {
        "ts": "2026-10-03T15:12:00Z",
        "type": "Debit card purchase",
        "merchant": "Grocery store",
        "amount_usd": 96.4
      },
      {
        "ts": "2026-10-05T14:00:00Z",
        "type": "Bill payment",
        "payee": "Credit card issuer (payee since 2014)",
        "amount_usd": 1193.97
      }
    ]
  },
  "questions": {
    "matches_customer": {
      "type": "noul",
      "instructions": "Does the vendor's alert refer to this customer's own login, account or card at our bank (including a card since closed or replaced), rather than to a different person?"
    },
    "still_exposed": {
      "type": "score",
      "instructions": "How likely is it that someone other than the customer can currently use the exposed data to sign in to this customer's online banking or make payments from the customer's accounts or cards?",
      "levels": [
        "Very unlikely (under 10%)",
        "Unlikely (10-40%)",
        "Uncertain (40-60%)",
        "Likely (60-90%)",
        "Very likely (over 90%)"
      ]
    },
    "response": {
      "type": "choice",
      "instructions": "What should the bank do about this alert for this customer?",
      "options": {
        "no_action": "Log the alert and take no action: it doesn't match this customer, or nothing it exposes still works",
        "reset_step_up": "Force a password reset from a device not named in the alert, end all sessions, remove trusted devices and require a one-time code at the next sign-in",
        "reissue_card": "Block the exposed card and issue a new card number; online banking access needs no change",
        "restrict_contact": "Restrict outbound payments, new payees and contact-detail changes until the customer is reached at the phone number on file"
      }
    }
  }
}
